Buyer guide
How to choose an IT provider
Twenty five questions, grouped by what they actually test. Most of them are uncomfortable to answer badly, which is the point. Use this on us as well as on everyone else you are considering.
The one question that matters most
If we leave, what do we receive and within how many days?
A provider comfortable answering this in writing is confident you will not want to. That confidence is the signal.
The twenty five questions
Send them in advance rather than asking on a call. Written answers are comparable, and a provider unwilling to put an answer in writing has told you something.
Set 01
Scope and delivery
- 01Which systems are covered, listed by name rather than described in general terms?
- 02Are onsite visits included, capped at a number of hours, or billed per trip?
- 03What is your response target, and is it contractual or aspirational?
- 04How do you measure response, and do you report response and resolution separately?
- 05Who will actually work our tickets, and will we deal with the same people?
- 06What happens to a fault that recurs every month?
Set 02
Security and risk
- 07What is in the security stack, by product name?
- 08Is security included in the fee or priced as an add-on?
- 09Do you carry cyber liability insurance, and what is the limit?
- 10Who pays for the labour of responding to a security incident on our network?
- 11How often do you test restores, and can you show me the last report?
- 12What is your own internal security posture, including MFA and access control?
Set 03
Commercial
- 13What is the term, the notice period, and does it auto renew?
- 14What triggers a price increase, and how much notice do we get?
- 15What is the onboarding fee and what does it cover?
- 16How are third party licences billed, at cost or with a margin?
- 17What is your after hours rate on covered systems?
- 18What is out of scope, listed explicitly?
Set 04
Exit and ownership
- 19Who owns the documentation you create about our environment?
- 20Who owns the credentials, and are they in a vault we can access?
- 21If we leave, what do we receive and within how many days?
- 22Do you use tooling that stops working the day we leave, and what breaks?
- 23Will you cooperate with an incoming provider during a transition?
Set 05
Fit
- 24How many clients do you support of roughly our size and in our sector?
- 25Can we speak to two of them, ideally one who has been with you over three years?
Six answers that should worry you
None of these are automatically disqualifying. All of them need a convincing explanation before you proceed.
A price before anyone looked at your systems
It is a guess, and guesses get corrected upward after signature.
Reluctance to name the security products
Either the stack is thin, or the person selling does not know it.
A single blended number for response and resolution
It hides which one is actually committed.
Vague or missing exit terms
This is where switching providers becomes expensive and slow.
No restore testing, or no report to show for it
An untested backup is an assumption rather than a safeguard.
Pressure to sign before the end of the month
Their quota is not your operational risk.
A scoring sheet that is not just price
Score each provider one to five on the criteria below, multiply by the weight, and total. Price is deliberately 15 percent, because a 10 percent saving on a provider who cannot restore your data is not a saving.
| Criterion | Weight |
|---|---|
| Scope clarity | 20% |
| Security depth | 20% |
| Response commitment | 15% |
| Exit and ownership terms | 15% |
| Sector and size fit | 15% |
| Price | 15% |
The reference call script
Every provider supplies happy references, so the goal is not to find out whether the client is satisfied. It is to find out how the provider behaves under pressure. Four questions do most of the work.
- Tell me about a time something went badly wrong. What happened and how did they handle it?
- Has response time stayed consistent as they have taken on more clients?
- Has the monthly fee changed, and were you given a reason and notice?
- If you were starting again tomorrow, would you choose them again?
The first question is the important one. A reference who says nothing has ever gone wrong is either a new client or is not going to be candid, and either way the call is not telling you much.
Common questions
Answered before you ask.
How many providers should we get quotes from?
Three is the practical number. One gives you no reference point, two turns into a coin toss on price, and beyond four the process consumes more management time than the decision is worth. Give all three the same information and the same asset list, otherwise you are comparing three different scopes rather than three providers.
What should we ask the references?
Ask what went wrong at some point and how it was handled, because every multi year relationship has at least one bad episode and the recovery tells you far more than the successes. Ask whether response has stayed consistent as the provider grew. Ask whether the monthly fee has changed and why. A reference who cannot recall anything ever going wrong is either new or not being candid.
Does size matter when picking a provider?
Fit matters more than size. A very large provider may deliver excellent tooling and process while treating a 25 person client as a rounding error. A single technician operating alone may be outstanding and also a single point of failure. What you are looking for is a provider where you are a meaningful client but not their largest, and where coverage does not depend on one person being available.
Should the cheapest quote be eliminated automatically?
No, but it should be interrogated hardest. Normalise all three quotes against the same scope before comparing, because a low price is usually achieved by excluding the security stack, excluding onsite work, or assuming a healthier environment than you actually have. If the cheapest quote survives normalisation with the scope intact, it may simply be a leaner operation, and that is a legitimate advantage.
Read next
The rest of the evaluation.
What managed IT services cost in Tacoma
Per user pricing bands, what moves the number up, and how to read a quote.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
IT contracts and SLAs explained
Auto renewal, out clauses, and who owns your data and documentation.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Use these questions on us first.
Send the list before you book anything. Written answers, no call required, and you can hold them against every other provider you are considering.